news.mlab.sh
Back to the feed
threat-intel

India says allegedly leaked nuclear plant files pose no safety risk

High
Summary

A cybercrime group, World Leaks (formerly Hunters International ransomware), has allegedly leaked thousands of files related to India's Kudankulam Nuclear Power Plant, claiming they originated from a breach involving Reliance Infrastructure and hosted by Yotta. While India’s nuclear operator insists the data doesn’t impact safety or security, and operations remain unaffected, the incident follows a previous malware attack linked to North Korea’s Lazarus Group in 2019. The group is demanding $1.5 million from Tata Electronics, highlighting a pattern of data theft and extortion.

India’s state-owned nuclear operator, Nuclear Power Corporation of India Limited (NPCIL), stated that documents recently published online and linked to the Kudankulam Nuclear Power Plant (KKNPP) do not pose any safety or security risks. The files, purportedly leaked by cybercrime group World Leaks (formerly Hunters International ransomware), include engineering drawings, supplier information, inspection records, and insurance documents related to Units 3 and 4, which are under construction near the southern tip of India.

World Leaks claimed the data originated from a breach involving Reliance Infrastructure, whose subsidiary Reliance Infrastructure is building non-nuclear infrastructure for the new Kudankulam reactors, and that the files were hosted on infrastructure provided by Indian data center provider Yotta. Yotta reported detecting suspicious activity on a Reliance Infrastructure server in late May, which it described as a suspected ransomware execution, and terminated the activity to prevent a potential attack.

NPCIL emphasized that the information relates only to conventional Balance of Plant (BoP) common service facilities and does not pertain to nuclear safety or security systems. The incident follows a previous cyber incident in 2019, when malware linked to North Korea’s Lazarus Group was discovered on an internet-connected administrative network at the plant, but operations were not affected.

World Leaks has claimed responsibility for breaching Tata Electronics, an Indian manufacturer that supplies Apple, Tesla, and Qualcomm, demanding $1.5 million and subsequently publishing alleged confidential engineering documents after the company refused to pay. The group’s tactics have shifted from traditional ransomware attacks to focusing on data theft and publication for extortion purposes.

Independent cybersecurity researcher Rakesh Krishnan initially documented the leak, noting that World Leaks published the data on June 11 after a countdown timer expired. He suggested potential intrusion vectors could include exposed remote desktop services, phishing, or exploitation of a Fortinet vulnerability, although no public evidence currently supports these claims. Neither Reliance nor Indian authorities have publicly attributed the intrusion or disclosed how the attackers gained access.

Read the full article at The Record